ZCyberNews
中文

#cisa-kev

7 articles

This archive collects 7 articles tagged cisa-kev published between April 19, 2026 and June 17, 2026, giving security teams a focused view of how this topic has appeared across ZCyberNews coverage. Recent coverage references CVE-2026-48907, CVE-2026-42271, and CVE-2024-57728, with each report tied to the specific vulnerability context available in the source article. The affected-scope signals emphasize government, technology, and media across North america, United states, and EU, helping readers compare exposure patterns without adding claims beyond the archive data. Severity coverage includes 2 critical, 3 high, and 2 medium reports.

CISA KEV catalog entry with Joomla JCE flaw highlightedCRITICAL
Vulnerabilities

CISA Adds Joomla JCE Flaw CVE-2026-48907 to KEV Catalog

CISA warns of active exploitation of CVE-2026-48907, a CVSS 10.0 improper access control flaw in Widget Factory Joomla Content Editor (JCE) allowing unauthenticated PHP code...

CVE-2026-48907
3 min read
Screenshot of CISA Known Exploited Vulnerabilities catalog entry for CVE-2026-42271HIGH
Vulnerabilities

CVE-2026-42271: LiteLLM Flaw Exploited in the Wild, CISA Adds to KEV

CISA added CVE-2026-42271 (CVSS 8.7) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against BerriAI LiteLLM deployments.

CVE-2026-42271
4 min read
CVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEVMEDIUM
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEV

CISA added CVE-2026-9082 (CVSS 6.5) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against all supported Drupal Core versions.

CVE-2026-9082
3 min read
CVE-2024-57728: SimpleHelp Path Traversal Lets Admins UploadHIGH
Vulnerabilities

CVE-2024-57728: SimpleHelp Path Traversal Lets Admins Upload

CISA adds CVE-2024-57728 to Known Exploited Vulnerabilities: SimpleHelp path traversal via zip slip allows admin users to upload arbitrary files and execute code. Due May 8, 2026.

CVE-2024-57728
3 min read
CVE-2025-2749: Kentico Xperience Path Traversal Under Active ExploitHIGH
Vulnerabilities

CVE-2025-2749: Kentico Xperience Path Traversal Under Active Exploit

CISA adds CVE-2025-2749 to KEV catalog: Kentico Xperience path traversal lets authenticated Staging Sync Server upload arbitrary files. Due date for federal agencies: May 4, 2026.

CVE-2025-2749
3 min read
NIST NVD Enrichment Change Creates CVSS Gap for 80% of CVEsMEDIUM
Industry News

NIST NVD Enrichment Change Creates CVSS Gap for 80% of CVEs

NIST now enriches only 15-20% of CVEs under new policy as of April 2026, leaving 80% without CVSS scores or product mappings.

3 min read
Microsoft Office Excel Flaw Exploited in Active AttacksCRITICAL
Vulnerabilities

Microsoft Office Excel Flaw Exploited in Active Attacks

CISA orders federal agencies to patch CVE-2009-0238, a 17-year-old Microsoft Office Excel remote code execution flaw, by April 28, 2026, due to active exploitation.

CVE-2009-0238
3 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.